ENGAGE - Server Displaying Sensitive Information
LowPublished Jan 10, 2025 · updated Jan 25, 2025
### Summary A vulnerability was found in engage platform, where an internal server error message exposes sensitive information about the servers, including SQL table which could lead to SQL injection. ### Severity Low - This vulnerability discloses partial information that is not immediately exploitable. ### Proof of Concept - Go to https://www.letsengage.com/google-form - File the form, enter text with some strange string encoding (I don’t exactly know what, looking at the error, something that latin1_swedish_ci cannot represent) in one of the input fields (I don’t know which one). - Go to the end of the form by filing all the inputs. - Click submit. - … - Get the error message. ### Timeline **Date reported**: 09/20/2024 **Date fixed**: **Date disclosed**: 1/10/2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Engage Product | all versions | No fix yet |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 92025 | Integer Overflow in eBPF DEVMAP map_delete_elem Leads to Out-of-Bounds | High7.8 | See the advisory |
| Jan 92025 | Linux Kernel: Integer Overflow in eBPF XSK map_delete_elem Leads to Out-of-Bounds | High7.8 | See the advisory |
| Jan 92025 | Linux Kernel: Out of bounds Write in ksmbd_vfs_stream_write | Critical9.8 | v6.13-rc2 |
| Jan 92025 | Linux Kernel: Out of bounds Read in ksmbd_vfs_stream_read | Critical9.1 | v6.13-rc2 |
| Dec 262024 | Apple: WebKit Canvas Denoising | Medium | No fix yet |
| Dec 232024 | MacPorts: Remote Code Execution | Medium | No fix yet |